Known vulnerabilities in thunderbird (Red Hat package) - page 19

Software CPE: cpe:2.3:o:red_hat:thunderbird_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 766
Public exploits: 17
Known exploited (KEV): 7
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting thunderbird (Red Hat package) thunderbird (Red Hat package) is affected by 766 known vulnerabilities: 7 critical, 358 high, 252 medium, 149 low Critical High Medium Low

Vulnerabilities (766)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU95500 - Multiple Interpretations of UI Input
CVE-2024-7529
CWE-450 Medium
No
No
115.14.0-1.el8_4, 115.14.0-1.el8_6 07.08.2024 SB20240806408
SB2024080774
SB2024080775
and 29 more
#VU95498 - Use After Free
CVE-2024-7528
CWE-416 High
No
No
115.14.0-1.el8_4, 115.14.0-1.el8_6 07.08.2024 SB20240806408
SB2024080775
SB2024081304
and 13 more
#VU95497 - Use After Free
CVE-2024-7527
CWE-416 High
No
No
115.14.0-1.el8_4, 115.14.0-1.el8_6 07.08.2024 SB20240806408
SB2024080774
SB2024080775
and 29 more
#VU95496 - Use of Uninitialized Resource
CVE-2024-7526
CWE-908 Medium
No
No
115.14.0-1.el8_4, 115.14.0-1.el8_6 07.08.2024 SB20240806408
SB2024080774
SB2024080775
and 29 more
#VU95495 - Permissions, Privileges, and Access Controls
CVE-2024-7525
CWE-264 Medium
No
No
115.14.0-1.el8_4, 115.14.0-1.el8_6 07.08.2024 SB20240806408
SB2024080774
SB2024080775
and 29 more
#VU95431 - Out-of-bounds read
CVE-2024-7522
CWE-125 High
No
No
115.14.0-1.el8_4, 115.14.0-1.el8_6 06.08.2024 SB20240806408
SB2024080774
SB2024080775
and 29 more
#VU95424 - Use After Free
CVE-2024-7521
CWE-416 High
No
No
115.14.0-1.el8_4, 115.14.0-1.el8_6 06.08.2024 SB20240806408
SB2024080774
SB2024080775
and 29 more
#VU95423 - Type confusion
CVE-2024-7520
CWE-843 High
No
No
115.14.0-1.el8_4, 115.14.0-1.el8_6 06.08.2024 SB20240806408
SB2024080775
SB2024081304
and 13 more
#VU95422 - Out-of-bounds read
CVE-2024-7519
CWE-125 High
No
No
115.14.0-1.el8_4, 115.14.0-1.el8_6 06.08.2024 SB20240806408
SB2024080774
SB2024080775
and 29 more
#VU95420 - Multiple Interpretations of UI Input
CVE-2024-7518
CWE-450 Medium
No
No
115.14.0-1.el8_4, 115.14.0-1.el8_6 06.08.2024 SB20240806408
SB2024080775
SB2024081304
and 13 more
#VU93898 - Memory corruption
CVE-2024-6604
CWE-119 High
No
No
115.13.0-3.el8_2, 115.13.0-3.el8_4, 115.13.0-3.el8_6, 115.13.0-3.el8_8, 115.13.0-3.el8_10, 115.13.0-3.el9_0, 115.13.0-3.el9_2, 115.13.0-3.el9_4 09.07.2024 SB2024070955
SB2024070975
SB2024071077
and 39 more
#VU93897 - Memory corruption
CVE-2024-6603
CWE-119 Low
No
No
115.13.0-3.el8_2, 115.13.0-3.el8_4, 115.13.0-3.el8_6, 115.13.0-3.el8_8, 115.13.0-3.el8_10, 115.13.0-3.el9_0, 115.13.0-3.el9_2, 115.13.0-3.el9_4 09.07.2024 SB2024070955
SB2024070975
SB2024071077
and 39 more
#VU93896 - Memory corruption
CVE-2024-6602
CWE-119 High
No
No
115.13.0-3.el8_2, 115.13.0-3.el8_4, 115.13.0-3.el8_6, 115.13.0-3.el8_8, 115.13.0-3.el9_0, 115.13.0-3.el9_2 09.07.2024 SB2024070955
SB2024070975
SB2024071077
and 30 more
#VU93895 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-6601
CWE-362 Medium
No
No
115.13.0-3.el8_2, 115.13.0-3.el8_4, 115.13.0-3.el8_6, 115.13.0-3.el8_8, 115.13.0-3.el8_10, 115.13.0-3.el9_0, 115.13.0-3.el9_2, 115.13.0-3.el9_4 09.07.2024 SB2024070955
SB2024070975
SB2024071077
and 39 more
#VU91693 - Use After Free
CVE-2024-5702
CWE-416 High
No
No
115.12.1-1.el7_9, 115.12.1-1.el8_2, 115.12.1-1.el8_4, 115.12.1-1.el8_6, 115.12.1-1.el8_8, 115.12.1-1.el8_10, 115.12.1-1.el9_0, 115.12.1-1.el9_2, 115.12.1-1.el9_4 11.06.2024 SB20240611267
SB2024061301
SB2024061401
and 36 more
#VU9495 - Permissions, Privileges, and Access Controls
CVE-2017-12363
CWE-264 Low
No
No
115.13.0-3.el8_8 01.12.2017 SB2017120105
SB2024072423
#VU9494 - Exposure of sensitive information to an unauthorized actor
CVE-2017-12365
CWE-200 Low
No
No
115.13.0-3.el8_8 01.12.2017 SB2017120104
SB2024072423
#VU9493 - Improper input validation
CVE-2017-12297
CWE-20 Low
No
No
115.13.0-3.el8_8 01.12.2017 SB2017120103
SB2024072423
#VU9492 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-12366
CWE-79 Low
No
No
115.13.0-3.el8_8 30.11.2017 SB2017120103
SB2024072423
#VU7121 - Memory corruption
CVE-2017-8487
CWE-119 High
Available
No
115.13.0-3.el9_0 15.06.2017 SB2017061408
SB20240718199


Showing elements 361 - 380 out of 766